US2014088736A1PendingUtilityA1

Consistency Analysis in Control Systems During Normal Operation

Assignee: MAN ANALYTICSPriority: Apr 18, 2012Filed: Apr 18, 2013Published: Mar 27, 2014
Est. expiryApr 18, 2032(~5.7 yrs left)· nominal 20-yr term from priority
Inventors:Frederick Cohen
G05B 9/03G05B 9/02
45
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A consistency analysis system provides consistency analysis for a control system that includes sensors for monitoring a number of different physical parameters. The analysis system uses a rules set and overlapping or redundant sensor data to determine alterations in system behavior or parameters even in the presence of subversion designed to alter or hide sensor trace data. Specific embodiments deliberate perturb the system or alters sensor data in order to detect whether other system or sensor data responds consistently to the perturbation. Specific embodiments also comprise associated methods performed by logic apparatus.

Claims

exact text as granted — not AI-modified
1 . An apparatus for detecting subversions of a system under control comprising:
 one or more data communication interfaces wherein at least one interface is configured to receive data from one or more sensors of one or more parameters of the system and at least one interface is configured to transmit control data to one or more effectors of the system;   stored perturbation information specifying how to determine allowable intentional alterations of effector control data and specifying how to determine expected sensor data that would result from the alterations;   one or more logic modules collectively configured to transmit and receive data on one or more data communication interfaces, to use the stored perturbation information, to apply the perturbations, to determine the expected sensor data, and to use the received data to perform one or more consistency checks between expected or predicted sensor data and detected sensor data as a result of alterations;   an output generator of said logic processor producing output identifying one or more of: presence of, absence of, or details regarding inconsistencies detected.   
     
     
         2 . The apparatus of  claim 1 , further wherein said stored perturbation information comprises one or more rules specifying control signals that produce systematic changes in the overall system and the expected changes that would be detected by sensors under such rules. 
     
     
         3 . The apparatus of  claim 1  wherein the perturbation information has been rigorously tested or otherwise verified to determine that resulting system perturbations are within the safety margins of the control envelope of the system. 
     
     
         4 . The apparatus of  claim 1  further wherein said stored perturbation information produces time variant effects within and throughout the system under control. 
     
     
         5 . The apparatus of  claim 1  further comprising:
 a scheduler module for applying different portions of said perturbation information in sequences so that a malicious actor wishing to alter the system will be unable to predict the proper responses in time to pass the consistency checks, even when the malicious actor has control of one or more of the sensors and effectors. 
 
     
     
         6 . The apparatus of  claim 5  further wherein:
 the scheduler module is configured to apply different portions of said perturbation information in random, pseudo-random or unpredictable sequences. 
 
     
     
         7 . The apparatus of  claim 1  further wherein computational advantage is used by the control system designer to detect and potentially diagnose malicious alteration. 
     
     
         8 . The apparatus of  claim 1  further comprising:
 a further set of consistency information and/or rules and/or facts comprising one or more rules and/or facts that describe or incorporate:
 laws of physics, 
 assumptions about the operating environment, 
 operating procedures normally followed, 
 statements of fact, 
 facts consistent with identified traces of activities, 
 hypotheses, 
 assertions based on human statements or testimony, and/or other 
 assertions of things that must normally be true or are specifically known or thought to be true; and 
 
 further wherein the consistency checker is configured to detect inconsistencies within and between elements in the set of information and/or rules and/or facts and/or sensor and/or effector data. 
 
     
     
         9 . The system of  claim 1  further wherein:
 the set of information and/or rules and/or facts contains methods for checking consistency of traces stemming from operations of a physical system and facts gathered from said physical system. 
 
     
     
         10 . The system of  claim 1  further wherein:
 the set of information and/or rules and/or facts contain information and/or rules and/or facts determined by or determining time, place, or other physical events related to operations. 
 
     
     
         11 . The apparatus of  claim 1  further comprising:
 a hardware processor; 
 a computer-readable medium carrying at least one sequence of instructions to access rules and facts and perform consistency checking. 
 
     
     
         12 . A security system for a controlled system comprising:
 control system data storage storing default and configuration data of the controlled system;   perturbations data storage storing data regarding one or more perturbations and expected responses for the perturbations;   control system interfaces configured to communicate with a plurality of sensors and effectors operating in a system under control;   consistency data storage storing data for consistency analysis of data traces from the plurality of sensors and effectors and other available controlled system data;   security system processor or processors comprising one or more processing elements, wherein the security system processor or processors is in communication with the data storage and the control system interfaces and wherein the security system processor is programmed or adapted to perform the steps comprising:   receiving control system data from said one or more sensors and effectors;   performing a consistency analysis on the control system data;   reading one or more perturbations from said perturbation data storage;   selecting one or more perturbation routines;   causing the selected one or more perturbation routines to be executed, wherein the selected one or more perturbation routines can be executed by the control system, the security system, or by combinations thereof;   wherein the selected one or more perturbation routines are expected to cause at least one detectable response in one or more effectors or sensors, without causing operation of said controlled system outside of allowed parameters;   receiving control system data from said one or more sensors and effectors under perturbation;   performing an expectancy and/or consistency analysis on the control system data under perturbation;   reporting results of the expectancy and/or consistency analysis on the control system data under perturbation when any value indicates an unexpected and/or inconsistent result to the perturbation.   
     
     
         13 . Non-transitory machine-accessible and readable media comprising software that, when executed by a control system with logic processing and data interface capabilities and operating on a system under control, configures the control system to:
 apply one or more deliberate alterations to the system under control;   read sensor data from one or more sensors connected to the system under control;   use consistency data to determine if the sensor data is consistent with the one or more deliberate alterations; and   report one or more of presence of, absence of, or details regarding any inconsistencies detected.   
     
     
         14 . A method for detecting subversions of a system under control comprising:
 applying one or more deliberate alterations to the system;   reading sensor data from one or more sensors connected to the system;   using consistency data to determine if the sensor data is consistent with the one or more deliberate alterations;   reporting one or more of presence of, absence of, or details regarding any inconsistencies detected.   
     
     
         15 . The method of  claim 14  further comprising:
 reading alteration information specifying allowable deliberate alterations and expected sensor data that would result from the alterations. 
 
     
     
         16 . The method of  claim 14  further comprising:
 verifying alteration data to determine that resulting system perturbations are within the safety margins of the control envelope of the system. 
 
     
     
         17 . The method of  claim 14  further comprising:
 applying one or more deliberate alterations that produce time variant effects within and throughout the system under control. 
 
     
     
         18 . The method of  claim 14  further comprising:
 applying deliberate alterations in sequences so that a malicious actor wishing to alter the system will be unable to predict the proper responses in time to pass the consistency analysis even when the malicious actor has control of one or more of the sensors and effectors. 
 
     
     
         19 . The method of  claim 15  further wherein:
 applying deliberate alterations comprises applying different alterations in random, pseudo-random or unpredictable sequences. 
 
     
     
         20 . The method of  claim 14  further wherein computational advantage is leveraged to detect and potentially diagnose malicious alteration. 
     
     
         21 . The method of  claim 14  further comprising:
 determining one or more possible explanations of a detected inconsistency and reporting those explanations.

Join the waitlist — get patent alerts

Track US2014088736A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.